First published: Wed Apr 01 2020(Updated: )
An issue was discovered in Deskpro before 2019.8.0. This product enables administrators to modify the helpdesk interface by editing /portal/api/style/edit-theme-set/template-sources theme templates, and uses TWIG as its template engine. While direct access to self and _self variables was not permitted, one could abuse the accessible variables in one's context to reach a native unserialize function via the code parameter. There, on could pass a crafted payload to trigger a set of POP gadgets in order to achieve remote code execution.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Deskpro Deskpro | <2019.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-11467 is a vulnerability in Deskpro versions before 2019.8.0 that allows administrators to modify the helpdesk interface and can result in remote code execution.
The severity of CVE-2020-11467 is rated as critical, with a CVSS score of 7.2.
Deskpro versions up to and excluding 2019.8.0 are affected by CVE-2020-11467.
To fix CVE-2020-11467, upgrade to Deskpro version 2019.8.0 or later.
The CWE (Common Weakness Enumeration) for CVE-2020-11467 is CWE-502.